Problem with ldap-sudo



i have here ldap with sudo. It works, but here is an example. Two groups, one wheel:

Code:
dn	cn=%wheel,ou=SUDOers,ou=Anwendungen,dc=osit,dc=cc
 	cn	%wheel
 	description	Superadmingruppe
 	objectClass	sudoRole
top
 	sudoCommand	ALL
 	sudoHost	ALL
 	sudoUser	%wheel
This works fine. And the second. One Group for on command without password:

Code:
dn	cn=Systemservice-Administrator,ou=SUDOers,ou=Anwendungen,dc=osit,dc=cc
 	cn	Systemservice-Administrator
 	objectClass	sudoRole
top
 sudoCommand	
/usr/bin/systemctl
/sbin/service
/usr/sbin/service
/usr/bin/journalctl
/usr/bin/timedatectl
 	sudoHost	ALL
 	sudoOption	!authenticate
 	sudoUser	%Systemservice-Administrator
this works also great, but only when an user is only in this one group, when a user is in wheel an Systemservice-Administrator, then the user must always enter an password, also on the commands from the Systemservice-Administrator Group. What must i change that this works? Here are my defaults:

Code:
cn=defaults,ou=SUDOers,ou=Anwendungen,dc=osit,dc=cc
 	cn	defaults
 	description	sudoOption's
 	objectClass	sudoRole
top
 	sudoOption	!root_sudo
!lecture
log_host
log_year
ignore_dot
passwd_tries=3
ignore_local_sudoers
timestamp_timeout=5
passwd_timeout=1
authenticate
Thanks and Regards